A security researcher discovered that an open field for entering a phone number unintentionally turned AirTags into a gift for cybercriminals.

See also: Android malware has stolen money from 10 million users!
One of the most terrifying aspects of mobile IT in 2021 is that simplicity and convenience are very enticing in small devices (think AppleWatch, AirTags, even bells that monitor health conditions, smart headphones, etc.).
Compared to the predecessor laptops and desktop computers, they make it much harder to verify whether URLs are correct, that texts/email SPAM/malware do not open, and that employees follow the minimal cybersecurity precautions required by IT. In short, as ease of use increases, security risks also increase.
Another reality of cybersecurity that has always been, is that small programming errors are easy to make and are often overlooked. Yet, these small mistakes can lead to huge security holes. This brings us to Apple and Airtags.
See also: FinFisher malware: Infects Windows Boot Manager with UEFI bootkit
A security researcher found that an open field for entering a phone number has unintentionally turned AirTags into a gift from God for cybercriminals.
«The security consultant and penetration tester Bobby Rauch discovered that Apple’s AirTags – tiny devices that can be placed on objects that are often lost, such as laptops, phones or car keys – do not perform «sanitize» on user input. This vulnerability opens the door for using AirTags in a drop attack. An attacker can use a maliciously prepared AirTag for whatever purpose they want», the publication said.».
«This type of attack does not require much technological expertise – the attacker simply types a valid XSS into the AirTag phone number field, then puts the AirTag into Lost mode and “drops” it somewhere where the target is likely to find it. Theoretically, scanning a lost AirTag is a safe action – it is assumed that only a webpage at https://found.apple.com/ will appear. The problem is that found.apple.com then embeds the content of the phone number field into the site, as shown in the victim’s browser.»
The worst part of this security hole is that the damage it can cause is limited only by the attacker’s creativity. Being able to input almost any URL into this window, combined with the fact that victims are unlikely to bother investigating what is actually happening, can achieve anything.
This is the reason why using devices such as AirTags is dangerous. Their small size and the ability for a single person to operate them make them appear harmless, which is not the case. The fact that any device can communicate with anyone or anything at the device's will (IoT and IIoT door locks, bulbs, temperature sensors and more) is a significant threat. It threatens consumers, but it is a much more dangerous threat for IT and security businesses.
See also: Microsoft: New FoggyWeb malware is a backdoor for hackers
Employees and contractors tend to forget everything they know about cyberspace when interacting with these small devices. Some of these devices – including AirTags and smartwatches – make it impossible for end-users to be cyber-vigilant. That AirTags can cause this nightmare is a reminder of what hackers are capable of.
Information source: computerworld.com
